Executive Summary
A vulnerability, CVE-2026-101045, was discovered in Fleet's macOS app install and uninstall scripts. These scripts, generated from Homebrew cask metadata, were not properly escaping shell metacharacters, allowing an attacker to inject arbitrary commands. This flaw could be exploited by an attacker who could place crafted metadata in an upstream Homebrew cask, potentially leading to arbitrary command execution as root on affected managed macOS hosts.
Technical Analysis
The vulnerability class of CVE-2026-101045 is a command injection vulnerability. The attack vector involves an attacker injecting shell metacharacters (e.g., $(...) command substitution) into Homebrew cask metadata. This metadata is then used to generate Fleet's macOS app install and uninstall scripts. The scripts, running as root, would execute the injected commands if the crafted metadata passed both upstream Homebrew cask review and Fleet's automated ingestion pull request review.
How It Gets Exploited
An attacker would need to craft malicious metadata for a Homebrew cask. This crafted metadata would contain shell metacharacters designed to inject arbitrary commands into the Fleet-generated scripts. The attacker would then need to get this metadata accepted into the upstream Homebrew cask and subsequently into Fleet's ingestion pipeline. Once the affected Fleet-maintained app was installed or uninstalled on a managed macOS host, the injected commands would execute as root.
Impact Assessment
The vulnerability affects Fleet versions before v4.92.0. The CVSS score for this vulnerability is 8, indicating a high severity level. An attacker could achieve arbitrary command execution as root on managed macOS hosts that install or uninstall the affected Fleet-maintained app. The scope of the vulnerability is changed (C), with high impacts on confidentiality (C:H), integrity (I:H), and availability (A:H).
Recommended Actions
- Ensure that your Fleet installation is updated to version v4.92.0 or later. This version includes the fix for CVE-2026-101045.
- Review and monitor your Fleet-managed macOS hosts for any suspicious activity related to app installations or uninstallations.
- Implement strict controls on who can modify Homebrew cask metadata that is used in your environment.
Sources
- National Vulnerability Database (NVD)
- Vulncheck